Doc CC-07Rev 2026-10Class study materialRead ~9 min
CISSP Domain 3: Security Architecture and Engineering (13%) — models, crypto and the traps
CISSP Domain 3 is Security Architecture and Engineering: 13% of the ISC2 CISSP (Certified Information Systems Security Professional) exam under the current outline (effective April 2024), covering secure design, security models, evaluated systems, platform weaknesses, cryptography and PKI, and the building the servers sit in.
Exam readout
- Format
- CAT, every language
- Items
- 100–150
- Time
- 3 hours
- Pass mark
- 700 / 1000 scaled
- Outline
- 8 domains · Apr 2024
Weight
13%
current outline, effective April 2024
Same weight as
D4 · D5 · D7
only D1, at 16%, is heavier
Formulas to memorize
2
n(n−1)/2and2nDepth console
12 items
original practice items, D3 only
What Domain 3 covers, in one pass
Domain 3 is where the exam stops asking what the business should do and starts asking how the thing is built. Its scope runs from design principles down to the sprinkler heads in the server room, and consecutive items will jump between the two without apology.
- Design and models — secure design principles, Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash.
- Systems — control selection, the trusted computing base, TPM, Common Criteria, and weaknesses of cloud, container, serverless, IoT and industrial platforms.
- Cryptography — algorithms, key management, PKI, signatures and the attacks on them.
- Site and facility — location, power, HVAC, fire suppression.
The paraphrase is ours; the binding wording is the ISC2 exam outline. How the weight shows up in an adaptive session is on the exam format page; the other seven domains are on the study guide hub. Few D3 items ask for a definition. Most give you a scenario and ask which model, algorithm or control fits, so learn what each mechanism protects — and what it does not.
Security models: who blocks what
| Model | Protects | Core rules | How the question gives it away |
|---|---|---|---|
| Bell-LaPadula | Confidentiality | No read up (simple security property); no write down (*-property) | Classified data, clearances, worry about leaks |
| Biba | Integrity | No read down (simple integrity axiom); no write up (* integrity axiom) | Trusted data contaminated by less trusted sources |
| Clark-Wilson | Integrity, commercial | Access triple subject–program–object; data changes only through well-formed transactions; separation of duties | Users never touch the data directly — everything goes through an application |
| Brewer-Nash (Chinese Wall) | Conflict of interest | Access rights change with what the subject has already opened | Consultants or auditors serving competing clients |
| Take-Grant, Graham-Denning, HRU | Rights management | How rights are granted, transferred, created and deleted | The question is about passing rights, not about levels |
Bell-LaPadula says nothing about integrity, and Biba nothing about confidentiality. A scenario that needs both needs two models.
Secure design principles, read the exam’s way
- Least privilege
- Minimum rights for the minimum time. Removing standing admin rights beats monitoring them.
- Defense in depth
- Independent layers. Two layers that fail for the same reason count as one.
- Fail securely
- On error, deny: the application refuses access when the authentication service is down. Doors with people behind them follow the opposite rule — see site and facility design.
- Keep it simple
- Fewer interfaces, smaller attack surface. The principle everyone agrees with and then ignores at the design review.
- Zero trust
- No implicit trust from network location; every request is authenticated, authorized and re-evaluated. The older “trust but verify” perimeter is a different answer.
- Privacy by design
- Privacy built in from requirements onward, and on by default.
- Shared responsibility
- The cloud split moves with the service model — more on the provider in SaaS, more on the customer in IaaS — but the customer always owns its data and who can reach it.
The trusted base and how systems get evaluated
The reference monitor is the concept: it mediates every access, is tamper-proof and small enough to verify. The security kernel implements it in hardware, firmware and software. The trusted computing base (TCB) is everything the policy relies on. Distractors swap the three, so match each word to its level: concept, implementation, everything.
Evaluation and sign-off
Common Criteria (ISO/IEC 15408) is the scheme in use: a protection profile states what a product class must do, a security target what one product claims, and the result is an assurance level from EAL1 (functionally tested) to EAL7 (formally verified). TCSEC, the Orange Book, rated confidentiality only — know it well enough to rule it out. Certification is the technical evaluation; accreditation (authorization) is management accepting the residual risk, the same logic as in the Domain 1 guide.
On hardware, a TPM is a chip bound to one machine that stores keys and measures the boot chain; an HSM is a separate tamper-resistant device holding keys for many systems. Protection rings (ring 0 is the kernel) and memory protection answer how one process is kept out of another.
Vulnerabilities by platform
| Ref | Platform | Typical weakness | Answer pattern |
|---|---|---|---|
| R-01 | Cloud | Misconfiguration, weak identity controls, multitenant remanence | Read the shared-responsibility split first; identity and data stay with the customer |
| R-02 | Virtualization | VM escape and sprawl; one compromised hypervisor exposes every guest | Harden the hypervisor; isolate its management interface |
| R-03 | Containers | Shared host kernel, vulnerable base images, secrets baked in | Scan and sign images, minimal bases, run as non-root |
| R-04 | Serverless | Over-permissive function roles, injection via event data | One least-privilege role per function; validate every event |
| R-05 | ICS and SCADA | Unauthenticated legacy protocols, slow patch cycles | Segment from the corporate network; test patches offline; safety first |
| R-06 | IoT and embedded | Default credentials, no update path | Change defaults, isolate on its own segment, buy updatable |
| R-07 | Databases | Aggregation and inference: harmless items combine into something sensitive | Polyinstantiation, cell suppression — control the combination |
Industrial control questions often hide a safety angle: the right answer keeps people unharmed before it keeps data confidential.
Twelve Domain 3 items in the console
Original practice items, D3 only, with a note on every option. They train judgment; they do not forecast an exam result.
Domain drill
Item 01 / 12
Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.
An intelligence system is configured to strictly enforce both the Bell-LaPadula confidentiality model and the Biba integrity model simultaneously. What is the operational impact of applying these conflicting mandatory properties to all user interactions?
Rationale
Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.
Cryptography: what each tool gives you, and what it does not
Cryptography is the densest block of Domain 3 and the easiest to over-study. Nobody asks you to compute a round of AES; the exam asks you to match a goal — confidentiality, integrity, authentication, non-repudiation — to the mechanism that delivers it.
Symmetric vs asymmetric
Symmetric ciphers (AES, the retired DES and 3DES) share one key: fast, fine for bulk data, awkward to distribute. Asymmetric algorithms (RSA, ECC, Diffie-Hellman) use a key pair: slow, but they solve distribution and enable signatures. Real protocols such as TLS are hybrid — asymmetric to set up a session key, symmetric for the data. Keep the sizes: DES 56-bit key and 64-bit block; AES 128-bit block with 128-, 192- or 256-bit keys; ECC matches RSA strength with far shorter keys. By Kerckhoffs’s principle only the key is secret, so a secret algorithm is never the right control.
Hashes, MACs and signatures
A hash gives integrity only — no key, no secrecy. An HMAC adds a shared secret and proves origin, but both sides hold the key, so there is no non-repudiation. A digital signature signs the message hash with the sender’s private key; only it gives integrity, authentication and non-repudiation together.
PKI
A certificate authority binds a public key to an identity in an X.509 certificate; a registration authority verifies identity but cannot issue. Revocation is checked through a CRL or live via OCSP. Escrow encryption keys, never signing keys — a recoverable signing key breaks non-repudiation.
| Goal | Operation | Key used |
|---|---|---|
| Confidentiality to one recipient | Encrypt | Recipient’s public key |
| Digital signature | Sign the hash | Sender’s private key; verified with the sender’s public key |
| Bulk data | Encrypt with a session key | Symmetric key, wrapped with the recipient’s public key or agreed by Diffie-Hellman |
| Integrity and authenticity | HMAC | Shared secret key |
| Integrity only | Hash | No key |
Key counts: the arithmetic of Domain 3
Pick the formula by key type, not by which number looks more impressive.
Symmetric keys, n parties
keys = n(n − 1) / 2Every pair needs its own secret: 10 users → 45; 100 users → 4,950.
Asymmetric keys, n parties
keys = 2nOne key pair each: 10 users → 20; 100 users → 200.
Adding one user to n (symmetric)
new keys = nGoing from 10 to 11 users adds 10 keys.
Cryptanalytic attacks, sorted by what the attacker holds
- Ciphertext only — intercepted ciphertext and nothing else; the attacker’s weakest position.
- Known / chosen plaintext — some plaintext–ciphertext pairs, or the power to have chosen input encrypted.
- Brute force and dictionary — answered by key length, salting and slow password hashing.
- Birthday — two inputs, one hash; why MD5 and SHA-1 are unfit for signatures.
- Meet-in-the-middle — why 2DES adds almost no strength.
- Side-channel — timing, power or emissions leak the key without breaking the math.
- Replay — stopped by nonces, timestamps and sequence numbers.
- Pass-the-hash and Kerberos abuse — reuse a captured hash or ticket instead of cracking it.
The preferred fix is rarely a longer key. It is a correct implementation: salts, nonces, constant-time code, good randomness, keys kept out of source code.
Site and facility design
Candidates skip the physical part of Domain 3 because it sounds like building management, and it holds the exam’s most single-fact questions. Human life comes first, then the asset.
Put the data center in the core of the building — not the basement, which floods, nor the top floor. Sensitive rooms get walls that run slab to slab. CPTED (crime prevention through environmental design) uses sightlines, lighting and landscaping before anyone hires a guard.
- Spike / surge: momentary / prolonged high voltage. Sag / brownout: low. Fault / blackout: loss.
- A UPS bridges seconds to minutes, a generator the long outage.
- HVAC keeps positive pressure to push smoke out; dry air builds static, damp air corrodes.
| Class | Fuel | Suppress with |
|---|---|---|
| A | Paper, wood, cloth | Water, foam |
| B | Flammable liquids | CO₂, foam, clean agent |
| C | Energized electrical | CO₂ or clean agent — never water |
| D | Combustible metals | Dry powder |
| K | Cooking oils | Wet chemical |
Europe and Australia letter their classes differently.
Debrief · key takeaways
- Bell-LaPadula = confidentiality, Biba = integrity, mirror-image rules; simple = read, star = write.
- Symmetric
n(n−1)/2, asymmetric2n; only a signature gives non-repudiation. - Diffie-Hellman agrees a key — it neither encrypts nor authenticates.
- Life safety first, pre-action sprinklers, no water on class C.
- Next: the study plan for where D3 fits in your weeks.
Questions people ask
Q01What is Domain 3 in CISSP?
Security Architecture and Engineering, weighted at 13% in the current outline (effective April 2024): design principles, security models, system evaluation, platform vulnerabilities, cryptography and PKI, cryptanalytic attacks, and site and facility security.
Q02Is cryptography the hardest part of Domain 3?
It is the largest part, not necessarily the hardest. Cryptography and PKI take most of the reading, but the exam asks which algorithm, mode or key-management choice fits a scenario, not how to compute one. Security models and facility controls are shorter topics and still decide items; weigh your time by what you miss in the console above.
Q03How many Domain 3 questions are on the CISSP exam?
ISC2 publishes weights, not a per-domain count. The adaptive exam runs 100–150 items, so the number varies; 13% means Domain 3 is a bit more than one item in eight on average, mixed in with the other domains.
Q04Where can I practice CISSP Domain 3 questions?
The console above holds 12 original D3 items; the practice test mixes 60 across all domains. Neither reproduces adaptive scoring.
Where to go next
Field kit
Keep the practice going on your phone
The CISSP prep app carries a much larger question bank — on iPhone and Android.